Security

Your records are yours.

You should not have to take that on faith, and you should not have to decode a page of jargon either. Here is exactly how patient records are protected, in plain terms — ask us to demonstrate any of it.

Nobody else can see your patients

Your practice’s records are walled off from every other practice in two separate ways, at two different levels of the system. For one clinic to see another’s patients, both would have to fail at the same time — and the second is built so that anything arriving without a practice attached is refused outright rather than answered.

A stolen password is not enough

Signing in takes a second step: a code from your phone or your email. It is required for practice owners rather than suggested, and it takes a minute to set up once. Your backup codes are stored in a form that is useless to anyone who steals them.

The sensitive details are encrypted

Tax IDs, insurance policy and group numbers and your billing credentials are each encrypted in their own right, not just sitting on an encrypted disk. You can still search for a policy number; it just cannot be read straight out of the database.

Nothing can be changed behind your back

Once you sign a note it locks. A later correction is added to it, dated and signed, rather than replacing what was there. Payments are reversed rather than erased, keeping who did it and why. If a record is ever questioned, the full story is still there.

You can see who opened a chart

Every time a chart is opened it is recorded, in a log that cannot be edited or tidied up afterwards — not by your staff, and not by us. If you are ever asked who accessed a record, you have an answer.

Your team sees only what they need

Front desk, billing, associates and owners each get the view that fits their job, set per clinic. An associate can see what they billed without being able to change prices or take payments, so nobody carries more access than their role needs.

In practice

  • A BAA is signed before any patient data is entered — no exceptions, no upgrade required.
  • Sign-in and two-factor attempts are rate limited, and challenge codes expire in ten minutes.
  • Uploaded clinical documents are checked against an allow-list of file types and served only through an authorised request, never from a public URL.
  • Data is yours: export it in a portable format whenever you want, and we delete it on request.

Doing your own diligence and need something specific? Email[email protected] and you will get a direct answer from someone who worked on it.

Ready when you are

Want a look at it?

Tell us how you run your day and what your current software makes hard. If it is a fit we will show you the real thing, gaps included.

  • Early access
  • No card required
  • Founding pricing locked
  • BAA before any patient data